Unverified Password Change Vulnerability in Modicon PLCs by Schneider Electric
CVE-2018-7811
9.8CRITICAL
Key Information:
- Vendor
Schneider Electric
- Vendor
- CVE Published:
- 30 November 2018
What is CVE-2018-7811?
The vulnerability exists in the embedded web servers of various Modicon PLCs, allowing an unauthenticated remote user to exploit the system by accessing the change password function. This can potentially lead to unauthorized modifications and access to sensitive operational functions, thereby jeopardizing the security of the entire automation system. Mitigation strategies should be employed to secure web server access and ensure user authentication.
Affected Version(s)
Embedded Web Servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 Embedded Web Servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200